prospect-research-compiler
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize data from untrusted external sources, which creates a surface for indirect prompt injection.
- Ingestion points: Aggregates intelligence from news, social media, company websites, and financial data as described in the instructions (SKILL.md).
- Boundary markers: The instructions lack explicit delimiters or "ignore instructions" warnings when processing these external inputs.
- Capability inventory: The skill aggregates and compiles research, implying the use of search or web-retrieval tools to access the referenced external sources.
- Sanitization: There is no mention of sanitizing, filtering, or escaping content retrieved from external sources before it is processed by the agent.
Audit Metadata